« Volver al listado

CVE-2023-28361

Estado: ModificadaMedia (6.5)—

A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud Key Gen2Cloud Key Gen2 PlusUNVRUNVR ProfessionalUDMUDM ProfessionalUDM SEUDRMitigation:Update affected products to UniFi OS 3.0.13 or later.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-28361",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-28361",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-27T16:43:36.396524Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "support@hackerone.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "UniFi OS",
          "versions": [
            {
              "status": "affected",
              "version": "Fixed in UniFi OS 3.0.13 or later."
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-05-11T22:15:10.187",
  "references": [
    {
      "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-030-030/f9de9e65-585f-4c66-81e9-5d8f54ba66dd",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://community.ui.com/releases/Security-Advisory-Bulletin-030-030/f9de9e65-585f-4c66-81e9-5d8f54ba66dd",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "support@hackerone.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A Cross-site WebSocket Hijacking (CSWSH) vulnerability found in UniFi OS 2.5 and earlier allows a malicious actor to access certain confidential information by persuading a UniFi OS user to visit a malicious webpage.Affected Products:Cloud Key Gen2Cloud Key Gen2 PlusUNVRUNVR ProfessionalUDMUDM ProfessionalUDM SEUDRMitigation:Update affected products to UniFi OS 3.0.13 or later."
    }
  ],
  "lastModified": "2026-06-17T05:47:32.797",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:uni:unifi_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "484887CC-286A-4C59-854A-06616BF3198B",
              "versionEndExcluding": "3.0.13"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:uni:cloud_key_gen2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "48EFCCAA-76C0-417B-BCED-BB6C9D0CBE8B"
            },
            {
              "criteria": "cpe:2.3:h:uni:cloud_key_gen2_plus:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1F171730-7AD1-46B3-ADAF-27BD69E7CC88"
            },
            {
              "criteria": "cpe:2.3:h:uni:ubiquiti_networks_unifi_dream_machine:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3BF09341-2DD2-4DCF-AEEA-67A6AEF2F0C5"
            },
            {
              "criteria": "cpe:2.3:h:uni:ubiquiti_networks_unifi_dream_machine_professional:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F8E72337-FAB2-4AB3-A8F8-7D32A1CEB17A"
            },
            {
              "criteria": "cpe:2.3:h:uni:ubiquiti_networks_unifi_dream_machine_se:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "ED78B144-E2FE-4648-BAD9-5079C0FB6255"
            },
            {
              "criteria": "cpe:2.3:h:uni:unifi_dream_router:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8A6CDD1F-DA20-4199-8D2D-60066D83D538"
            },
            {
              "criteria": "cpe:2.3:h:uni:unifi_protect_network_video_recorder:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "27F9EEC7-3D49-4FB0-8CD0-94CAB5651DE0"
            },
            {
              "criteria": "cpe:2.3:h:uni:unifi_protect_network_video_recorder_professional:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8E263DAE-C5DB-4642-9CA9-B56C098C8A1E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "support@hackerone.com"
}